Aadhaar verification · consent first
The holder decides what you see
Aadhaar is the most tightly governed identity in India. Using it well means asking for less, getting consent every time and never showing the full number. This guide explains the methods, who may use them, and the questions to settle with your lawyer first.
Example Lending asks to verify your identity
Choose what to share. You can say no.
- Name
- Photo
- Year of birth
- Full address · not needed
Aadhaar number shown masked; last four digits 4821
Share selected details
Signature validShared details carry UIDAI's digital signature and haven't been altered.
- 1AskSay what you'll verify and why, and ask only for what the purpose needs.
- 2The holder choosesThey share only the details you asked for, or say no.
- 3VerifyCheck UIDAI's digital signature on what was shared.
- 4Keep littleStore the result, not more Aadhaar data than the rules allow.
Settle these before you build anything
Aadhaar is governed by the Aadhaar Act and UIDAI's regulations, including the Aadhaar (Authentication and Offline Verification) Regulations, 2021. They decide who may use Aadhaar, for what, and how its data is handled. This guide explains how the methods work; it isn't legal advice, and each question below needs a lawyer's answer for your business.
- 01Are we permitted to use Aadhaar for this purpose at all?
- 02Which method may we use: online authentication through an approved entity, or offline verification?
- 03Do we need to register with UIDAI, or work through an entity that is registered or approved?
- 04What may we collect and store, and how must we display and protect it?
- 05What do we offer customers who choose not to use Aadhaar?
- 06If we're a regulated entity, what do our own regulator's KYC rules require?
Online authentication and offline verification
UIDAI draws the key line between two families of checks. The difference is whether the check contacts UIDAI's Central Identities Data Repository (CIDR) at all.
Online authentication
A request goes to UIDAI's CIDR and a response comes back: for example, to confirm an OTP sent to the holder's registered mobile number. It's available only through entities UIDAI has approved for authentication, under agreements and compliance requirements UIDAI sets.
Offline verification
Identity is verified without sending a request to, or receiving a response from, the CIDR. The holder shares Aadhaar data that UIDAI has digitally signed, and the verifier checks that signature. UIDAI calls entities that do this Offline Verification Seeking Entities (OVSEs).
The offline methods
| Method | What the holder shares | What the verifier checks |
|---|---|---|
| Aadhaar secure QR code | The QR code on their Aadhaar letter or e-Aadhaar | The digitally signed data in the QR code |
| Aadhaar paperless offline e-KYC | A digitally signed file they download from UIDAI | The signature and the data inside the file |
| Aadhaar App verifiable credentials | Credentials from the Aadhaar App, fully or in part, with their approval | UIDAI's digital signature on the credential |
| e-Aadhaar | The electronic Aadhaar document | The digital signature on the document |
As described in UIDAI's Aadhaar offline verification handbook. Entities wanting to verify Aadhaar App credentials apply to UIDAI to register as OVSEs.
Consent, and sharing only what's needed
UIDAI describes informed consent as a key feature of offline verification: the verifying entity must seek the holder's consent before any Aadhaar data is shared or verified. The holder also keeps the ability to disclose selectively, sharing only the attributes the purpose actually needs.
Design for that. If you only need to know someone is over 18, don't ask for their date of birth; if you don't need their address, don't ask for it. Every attribute you don't collect is one you don't have to protect.
Say why. One sentence on the purpose, shown before the holder shares anything.
Ask for less. Only the attributes the purpose needs.
Make no a real option. An alternative route, where your rules allow one.
Record the consent. When it was given, for what, and what was shared.
The number itself
An Aadhaar number is the one piece of data you should assume you may not keep. Whether your business may collect or store it at all, and how, is set by law and depends on who you are, so settle it with your lawyer before any screen asks for it.
Wherever it does appear, show it masked, with only the last four digits visible. Keep it out of logs, spreadsheets, support tickets and emails, where it tends to leak.
XXXX XXXX 4821
How an Aadhaar number should appear on any screen that shows it at all.
Aadhaar in KYC
For RBI-regulated entities, proof of possession of Aadhaar number is one of the officially valid documents in RBI's KYC Master Direction, and the Direction sets out how it may be used. It sits alongside the passport, driving licence, voter's identity card and others.
For everyone else, it's one possible route among several, and often not the simplest one to get right. The KYC guide covers the other layers.
| Need | Aadhaar route | Alternatives |
|---|---|---|
| Identity and address at onboarding | Offline verification, where permitted | Other officially valid documents |
| Confirm a taxpayer | Not needed | PAN verification |
| Confirm where to pay | Not needed | Bank account verification |
| Confirm a business | Not the right tool | KYB |
Designing a flow where Aadhaar is one option
For most businesses that may use Aadhaar at all, the safest design treats it as one route among several, not the front door. The customer sees the options, picks the one they're comfortable with, and gets to the same outcome either way.
That also protects you. If your permission to use a method changes, or a customer objects, the flow still works, and you haven't built your whole onboarding on a route you may have to switch off.
Verify your identity
- Share Aadhaar details from the Aadhaar AppChoose which details to share
- Upload another IDPassport, driving licence or voter ID
- Visit a branch or agentBring the original document
Mistakes that create risk
Photocopies on file
Keeping full Aadhaar copies “just in case”, where no rule requires it.
Numbers in plain sight
Full numbers in spreadsheets, CRMs or support tickets.
No alternative
Making Aadhaar the only way to sign up.
Unapproved routes
Using a provider's Aadhaar check without knowing under which UIDAI arrangement it runs.
Keeping Aadhaar out of places it shouldn't be
Most Aadhaar data leaks aren't breaches of the main database; they are copies in the wrong place: an export, a log line, an email attachment, a support ticket. If your permitted flow involves Aadhaar data at all, map every place it can travel, keep it out of logs and exports by design, and restrict and record who can see it. What you may store in the first place is still the legal question above.
Aadhaar verification questions
Plan identity checks with us
We'll walk through which checks fit your onboarding, including routes that don't need Aadhaar.
Talk to PeneuWhat is selective disclosure?
The Aadhaar holder's ability to share only some attributes, for example a name and photo but not an address. UIDAI describes it as part of offline verification: the holder shares what the verifier needs and nothing more.
Is a photocopy of an Aadhaar card a verification?
Not by itself. A photocopy can be altered and doesn't prove the person in front of you is the holder. The offline methods UIDAI describes rely on UIDAI's digital signature on the shared data, which is what makes them verifiable.
Does offline verification mean no internet is needed?
Not necessarily. "Offline" refers to not contacting UIDAI's central repository for the check. The holder and the verifier may still use apps and the internet to share and check the digitally signed data.
What should I tell customers before asking for Aadhaar details?
What you'll verify, why, which details you're asking for, what you'll keep and for how long, and what they can do instead if they'd rather not use Aadhaar. Say it before they share anything.
What is the difference between Aadhaar authentication and offline verification?
Online authentication sends a request to UIDAI's Central Identities Data Repository and gets a response. Offline verification, as UIDAI describes it, checks the holder's identity without sending a request to or receiving a response from that repository, using Aadhaar data the holder shares and UIDAI's digital signature on it.
Can any business verify Aadhaar?
No. Aadhaar is governed by the Aadhaar Act and UIDAI's regulations, which limit who may use it and for what. Online authentication is available only through entities UIDAI has approved for it, and entities that want to use certain offline methods apply to UIDAI to register as Offline Verification Seeking Entities. Whether and how your business may use Aadhaar is a legal question.
What are the offline verification methods?
UIDAI's offline verification handbook describes the Aadhaar secure QR code, Aadhaar paperless offline e-KYC, verifiable credentials shared from the Aadhaar App, and validating the digital signature on an e-Aadhaar.
Is consent required?
Yes. UIDAI describes informed consent as a key feature of offline verification: the verifying entity must seek the holder's consent before any Aadhaar data is shared or verified, and the holder can choose to share only the details the purpose needs.
Can I store a customer's Aadhaar number?
Treat this as a legal question before you build anything. The rules on collecting, storing and displaying Aadhaar numbers are strict and depend on who you are and why you need it. Where you don't need the number, don't collect it; where you show it, show it masked.
Is Aadhaar accepted for KYC?
For RBI-regulated entities, proof of possession of Aadhaar number is one of the officially valid documents listed in RBI's KYC Master Direction. It's one option among several, not the only one.
What if a customer doesn't want to use Aadhaar?
Offer another route wherever your rules allow one: another officially valid document, or a different verification method. Consent that can't be refused isn't really consent.
Does Peneu provide Aadhaar verification?
Which Aadhaar methods, if any, are available through Peneu, and under which UIDAI arrangement, is confirmed during onboarding. Nothing on this page should be read as Peneu offering Aadhaar authentication.
Official sources
- UIDAI — Aadhaar offline verification handbookOffline verification without the CIDR, OVSEs, the offline methods, consent and selective disclosure, OVSE registration.
- RBI — Master Direction – KYC, 2016 (updated 14 Aug 2025)Proof of possession of Aadhaar number as an officially valid document.
Last reviewed . Examples, amounts and screens marked illustrative are not Peneu figures.
